Return to Threats

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

thehackernews.com 2026-09-11 AI supply chain High

What Happened

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that

Why It Matters

Report facts: PaperCut has released new regular maintenance versions (26.0.5, 25.0.13, 24.1.10) that replace prior emergency patches for two security vulnerabilities that were actively exploited, indicating ongoing remediation in a widely used print management product. These versions are now available for customers to download as the preferred fix path. RealGround analysis: While the article does not mention AI directly, compromises of core IT infrastructure such as PaperCut can be part of an AI supply chain risk, allowing attackers to pivot into environments that host AI systems or training data. Organizations should treat such actively exploited software flaws as supply chain exposure and ensure patch management, SBOM tracking, and dependency-risk reviews cover components that may indirectly support or host AI workloads.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html

Talk to AI CISO